If a breach meant the firing of the CEO and the CTO and the board, then you'd know that companies would spend a lot more on security and privacy.
If a breach meant the firing of the CEO and the CTO and the board, then you'd know that companies would spend a lot more on security and privacy.
Weird.
Which means nothing gets done because it's pretty hard to prove where any one misusing your information got it from. My identity was stolen after breach but when I took it up with entity that lost my information, they were like "Prove it" which of course I couldn't because people who did it to me were never caught.
And many mail hosting services let you assign a catch-all, which allows you to simply use anything@mydomain.com to get the same result.
Big companies do this. I have signed up for things using a +filter email address, only to receive the emails from that company that is signed up to get at my plane address, without the +filter part.
Even if you can enter it, various backends in the same company might not handle it correctly and you enter up with an half-working account that their customer support (if they even have that...) cannot solve. Been there, tried that...
Personally I have - as the separator (not on gmail or similar). If you have to give you email on the phone it can cause lengthy discussions why their company name appears in my email address..
I haven't had issues with it in many years.
Okay. So now you, individually, may be able to attribute some sort of responsibility in some sort of civil action.
Penalties that companies care about aren’t going to be built around some very non-standard individual’s ability to maybe, sometimes, attribute blame.
Plus, the real damaging stuff wont have anything to do with your email addresses.
So I disagree, we don't need to wait until the data breaches lead to any particular outcomes, we need laws that make it clear that data breaches alone constitute damages to the people whose data was released. More people should be protected by GDPR-style laws, and more companies need to recognise that data security is something they need to take deeply seriously.
GDPR has been with us since 2018, and it if was the deterrent that everyone claimed it to be, we wouldn't be having this discussion today.
Who decides what a "severe" outcome is? The companies themselves? Why don't we hold them to a higher standard?
a) everyone is impacted by climate change, not just the customers who gave their data
b) climate change has very real consequences for people
Read up on the SSN leak from last week, I didn't give them my data. And it can have real consequences.
but this is the correct justification. If the customer is the one buying these products that cause climate impact, why is it the sole responsibility of the company to pay the cost of rectification?
In such situations, where externality is problematic, it is up to the gov't to push regulations to prevent it. A carbon capture tax, for example, is one such way.
> Why don't we hold them to a higher standard?
why should companies be held to a higher standard than a person?
It isn't - it's the company's responsibility to pass the cost to the customer.
It's similar with climate change. It's just a fact of the matter that people at scale only react as actual consequences become palpable.
1% of users in a data leak having their identities stolen or 1% of the cities in the world becoming uninhabitable due to heat isn't enough to demand action, what about 10%? Is 25% where we draw the line?
That's what imposing a 'severe' outcome would mean. You're using circular logic to be against a statement of facts.
A more practical policy proposal would criminalize extreme negligence while focusing on financial penalties for lesser beaches. Possibly the young missing vs current policies is that the duty to protect user data should probably increase with the amount of data collected - the juicier target you make your company, the more the penalty needs to hurt. This could mean companies taking a hard look e.g. at whether they really need your address and phone number because every extra bit of hacked information should cost them more.
When your license is your bread & butter and you cannot work without it, losing it is devastating—and much more devastating than losing a particular position at some company (so even if you are required to implement an insecure solution, you would have no problems telling respective manager to shove it, respectfully).
Why? The majority of situations where you need an account can be replaced with pseudonymous info.
Netflix needs an account and some payment data (which can itself be a pseudonymous card number with no identifying info attached), but it doesn't need to know my name or anything else.
I can see that the whole advertising/data broker/"growth & engagement" crowd would end up begging on the streets, but I'm not sure many actually valuable businesses would be affected all that much.
What I find surprising more that the usual lack of accountability in these cases is how little its impact tends to be felt on Wall Street. A slight dip in the share price maybe for a week or so, but then it's back to business as usual.
What if you log all POST requests for debugging purposes and forget to sanitize the logs.
What if you have XSS in your web app that sends the password to a third party.
What if your mobile phone app has a dependency that includes a keylogger.
The likelihood of this increases the more layers you have in your organization (for example, the log pipeline team assumes the logs are already sanitized; the login form team assumes the log team is sanitizing them; it all goes through some A/B testing team that just dumps all data to "data lake" somewhere unsafe; the FE team puts in random node.js dependencies as it's "just a frontend"; etc).
Passwords can leak from more places than just from the DB...
More likely they steal the app's credentials (db, cloud provider, etc) and then go to town on data at rest.
You're right on logs and things like fullstory, but no one on any team should assume things are sanitized. You do your job independently. If you're an infra, devops, sre, does it make sense to say I thought they had it handled? Was that what you marketed on your resume?
Not saying there aren't complexities involved, but in many of these cases I see a lot of low hanging fruit, likely due to moving too quickly. We really need to own up to the fact that we've grown too comfortable with not giving any thought to other people's data. Why is it that there are the PCI audits when you handle card data, but not when you handle PII? Because card fraud hits the banks and they don't want to pay for any of that. So an entire industry was spawned, it's not perfect, but it helps a lot. You do not see a lot of credit card leaks.
I do think it would incentivize new security products/libraries/services focused on helping companies fulfill their security requirements instead of rolling their own crappy solutions.
If a startup cannot secure their customer’s data effectively, I don’t want their product to exist. If that means fewer startups get products off the ground, I fail to see that as a bad thing if a lack of security was the reason.
Slowing the industry down after a decade of breach after breach after breach seems like a reasonable and possible necessary intervention.
Thus there is basically nobody doing credit card processing and the companies that DO that are unreasonably big and basically a monopoly. (Everyone always complains about PayPal...)